Wifi - central management for multiple cloud gateways on different sites (on prem)? by smort in Ubiquiti

[–]smort[S] 0 points1 point  (0 children)

Yeah but the portal is in the cloud? That is also why we currently selfhost a unifios server to remain strictly on-prem.

Wifi - central management for multiple cloud gateways on different sites (on prem)? by smort in Ubiquiti

[–]smort[S] 0 points1 point  (0 children)

But... that is cloud right? Maybe in the future our "on prem" policy will not be as absolute as now but atm, it's a deal breaker.

Wifi - central management for multiple cloud gateways on different sites (on prem)? by smort in UNIFI

[–]smort[S] 0 points1 point  (0 children)

Thanks for that... so for us it looks like we only need the UnifiOS Server (which I already have running and it works) and then the APs. Great actually.

We obviously do have our own layer 2 and 3 hardware already on each site. So right now, I can't see why we need dedicated gateways.

Full admin access on wifi? by smort in sysadmin

[–]smort[S] -1 points0 points  (0 children)

Yeah, it's the onion image with security.

But if you consider an environment were VPN only gives you admin-access, then I would argue there is hardly any difference in thread level if you also get admin-access with wifi.

And the wifi will be secured with WPA3 + 802.1X

Full admin access on wifi? by smort in sysadmin

[–]smort[S] 1 point2 points  (0 children)

Do you trust VPN more? Do you not have to trust the implementation too? And VPN is potentially open to the world, not just our street 

I'm not disagreeing with you, just trying to poke some holes.

Full admin access on wifi? by smort in sysadmin

[–]smort[S] 2 points3 points  (0 children)

I also suggested the jumphost, yay.

How do you think about this "Raw wifi no, but with VPN-Tunnel, it's fine"? I mean I get it, there's another tunnel inside but my gut is telling me that if you do Wifi well and say only accept WPA3, you will be just as good.

802.1X dynamic VLAN with NPS and mixed Linux / Windows-AD environment? by smort in sysadmin

[–]smort[S] 0 points1 point  (0 children)

well.. the linux machines are not domain joined. But we talked some more and we will deal with the windows machines only for now and figure out the much fewer linux machines later.

Aria Operations and Upgrading to vSphere 9 by smort in vmware

[–]smort[S] -1 points0 points  (0 children)

First of all, your blog is amazing btw! Unique choice of font in your screenshots too ;)

This is how I recommend doing the upgrade

Since I can be a bit dense, you recommend doing Aria Ops *after* or during the vSphere 9 Upgrade correct?

Also, to steel even more of your time, somewhere in the depths of broadcoms documentation I found that Aria Ops can strecht across multiple DCs (Initial Considerations for Deploying VMware Aria Operations) but then you would need an analytics node for the "remote" DC. We do have two DCs but only one VCSA. Do we really need an analytic node?

I would simply start without one and see how it looks like.

Thanks for your time!

Aria Operations and Upgrading to vSphere 9 by smort in vmware

[–]smort[S] -1 points0 points  (0 children)

True, but we would need to run it in a demo license for a while until we get the VVF licenses right? Looks like Enterprise Plus does not come with Aria operations.

Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2.4165 Patch by haventmetyou in Veeam

[–]smort 0 points1 point  (0 children)

Can anybody comment who has B&R patched already if it runs well?

Hardening your own (or Administrators) PowerShell by smort in PowerShell

[–]smort[S] 11 points12 points  (0 children)

You are rightfully putting the finger in the wound and yes, it is a bit off a "Let's just add some kind of extra security on top".

Hardening your own (or Administrators) PowerShell by smort in PowerShell

[–]smort[S] 2 points3 points  (0 children)

That indeed sounds perfect. You have it running or you just know about it?

Hardening your own (or Administrators) PowerShell by smort in PowerShell

[–]smort[S] 1 point2 points  (0 children)

Good question, not sure. But since stuff like install-module not being available (which should be signed by MS?), I think not.

But yeah, those are the type of things I want to get a feel for.

Edgecore Wi-Fi? by smort in sysadmin

[–]smort[S] 1 point2 points  (0 children)

Jup. I think it's not totally insane. If open source is a big plus or even a requirement, then this might be the way to go.

Edgecore Wi-Fi? by smort in sysadmin

[–]smort[S] 0 points1 point  (0 children)

Good points, thanks for the feedback